The US Secret Service is now pointing the finger at state-backed Chinese hackers, accusing a known advanced persistent threat group APT41 of stealing about $20 million of US Covid benefits during the pandemic.
The DoD has published a strategy and roadmap directing all the department's agencies to migrate to zero trust architecture by 2027. Strategy identified 90 target capabilities and 62 capabilities to achieve “more advanced zero trust.”
One of the few significant holes in Apple's end user security is set to be addressed, as Cupertino has announced plans to introduce end-to-end encryption to iCloud backups. A feature Apple has delayed due primarily to pressure from US federal law enforcement agencies.
Security leak of manufacturing keys from major device producers (such as LG and Samsung) allows signing of malware apps, providing full access to an Android device, as the operating system trusts any signed app with complete system-level access.
Ragnar Locker ransomware gang targeted the municipality of Zwijndrecht but instead hacked a local Belgian police unit, releasing sensitive police data, including investigation reports and criminal records.
A new report from the FPF and ABLI promotes a shift from consent-based models to a focus on accountability for data processors in the interest of improving consistency between different jurisdictions and different data protection laws.
UK MSPs will be brought under the same cybersecurity laws that govern essential services, such as critical infrastructure and health care. The move stems in large part from an increasing focus on MSPs by the most advanced nation-state security actors.
The battle against Log4Shell is proceeding very slowly due to a confluence of factors. It remains buried in a number of assets, particularly legacy systems that are tougher to address. But it also continues to affect organizations via new devices.
The South Dakota TikTok ban applies to the devices of government agencies, employees and contractors, put forward in the interest of protecting state and national security.
A spyware vendor in Spain has been linked to a zero-day exploitation framework that impacted Windows, as well as the Chrome and Firefox browsers, from 2018 to 2021. Google researchers present markers found in its code including a script that is signed by the company.










